FPGA-based Key Generator for the Niederreiter Cryptosystem Using Binary Goppa Codes

FPGA-based Key Generator for the Niederreiter Cryptosystem Using Binary Goppa Codes
复制标题

DOI:
10.1007/978-3-319-66787-4_13
复制
发表时间:
2017-09
期刊:
--
影响因子:
--
通讯作者:
Wen Wang;Jakub Szefer;R. Niederhagen
Wen Wang;Jakub Szefer;R. Niederhagen
中科院分区:
其他
文献类型:
--
作者:
Wen Wang;Jakub Szefer;R. Niederhagen

文献摘要

相似文献

本文提出了一种后量子安全,高效,可调的FPGA实现的密钥生成算法的Niederreiter密码系统使用二进制Goppa码。我们的密钥生成器实现只需896,052个周期即可生成密钥的公共和私有部分,并且在为Stratix V FPGA合成时可以实现超过240 MHz的估计频率Fmax。据我们所知,这项工作是第一个基于硬件的实现,其参数相当于或超过推荐的128位“后量子安全”级别。密钥生成器在不发生系统化故障的情况下仅需3.7ms即可生成参数、、和的密钥对,平均为1 ms。为了实现这样的性能,我们实现了一个优化的和参数化的高斯系统化矩阵,它适用于任何大规模的矩阵在任何二元字段。我们的工作还提出了一种基于FPGA的Gao-Mateer加性FFT的实现,它只需要大约1000个时钟周期就可以完成对一个119次多项式在数据点处的求值。我们的密钥生成器的Verilog HDL代码是参数化的,部分代码使用Python和Sage生成。它可以针对不同的参数进行合成,而不仅仅是本文中所示的参数。我们使用Sage参考实现、iVerilog仿真和真实的FPGA硬件对设计进行了测试。
This paper presents a post-quantum secure, efficient, and tunable FPGA implementation of the key-generation algorithm for the Niederreiter cryptosystem using binary Goppa codes. Our key-generator implementation requires as few as 896,052 cycles to produce both public and private portions of a key, and can achieve an estimated frequency Fmax of over 240 MHz when synthesized for Stratix V FPGAs. To the best of our knowledge, this work is the first hardware-based implementation that works with parameters equivalent to, or exceeding, the recommended 128-bit “post-quantum security” level. The key generator can produce a key pair for parameters,, andin only 3.7 ms when no systemization failure occurs, and inms on average. To achieve such performance, we implemented an optimized and parameterized Gaussian systemizer for matrix systemization, which works for any large-sized matrix over any binary field. Our work also presents an FPGA-based implementation of the Gao-Mateer additive FFT, which only takes about 1000 clock cycles to finish the evaluation of a degree-119 polynomial atdata points. The Verilog HDL code of our key generator is parameterized and partly code-generated using Python and Sage. It can be synthesized for different parameters, not just the ones shown in this paper. We tested the design using a Sage reference implementation, iVerilog simulation, and on real FPGA hardware.